Skip to Content
Quantum ReportsQuantum Reports
  • Article
  • Open Access

13 December 2022

Entropic DDoS Detection for Quantum Networks

HSBC Lab, 8 Canada Square, London E14 5HQ, UK

Abstract

Distributed Denial-of-Service (DDoS) attacks are a significant issue in classical networks. These attacks have been shown to impact the critical infrastructure of a nation, such as its major financial institutions. The possibility of DDoS attacks has also been identified for quantum networks. In this theoretical work, we introduce a quantum analogue of classical entropic DDoS detection systems and apply it in the context of detecting an attack on a quantum network. In particular, we examine DDoS attacks on a quantum repeater and harness the associated entanglement entropy for the detection system. Our results extend the applicability of quantum information from the domain of data security to the area of network security.

1. Introduction

A central aim of quantum information science is to design quantum systems that perform information tasks [1]. Prominent examples of such work involved deriving quantum analogues of classical information technologies and demonstrating an advantage by utilizing the quantum resource. For instance, the property of superposition is used by quantum models of computation to drastically outperform the best classical supercomputers on certain tasks [2,3]. Another example is the quantum analogues of classical communication networks which are simply referred to as quantum networks [4]. In such networks, quantum information can be teleported [5], notably to distances exceeding 1000 km [6]. Further protocols include secure key distribution which are predicated on the impossibility to copy quantum information [7].
Beyond this established work, a direction ahead is to design novel quantum information technologies by harnessing our understanding of the classical case. Our main result is to demonstrate progress in this area.
Distributed Denial-of-Service (DDoS) attacks are a significant issue in network security [8,9], and various methods have been developed to detect the attacks in classical networks. The possibility of DDoS attacks has also been identified for quantum networks [7,10,11,12]. In our theoretical work, we designed a detection system for such attacks that occur in this quantum setting.

2. Classical DDoS

In classical networks, information is transmitted in the form of data packets, and the role of directing this traffic is performed by routers. To initiate a DDoS flooding attack, many routers would direct packets from multiple attack nodes to a victim node. The intent behind this flood of traffic is to overload the victim node so that it becomes unresponsive to legitimate traffic.
DDoS attacks are rather frequent events [8,9], and their reach can extend into the critical infrastructure of a nation [13]. These include attacks on major financial institutions, such as banks [14,15] and exchanges [16].
Preventing a DDoS attack requires most essentially the ability to identify the attack traffic as early as possible [17]. To achieve this capability, detection systems have been designed using the Shannon entropy:
H ( X ) i p i log p i ,
where p i are the probabilities associated with random variable X, and logarithms are taken to base 2.
Reviews of such entropic approaches can be found in [9,17,18]. We briefly outline one of these methods [19].
A flow at a router is group of packets categorized as
f i j ( u i , d j , t ) { < u i , d j , t > | u i U , d j D } ,
where i , j Z + , U is the set of the upstream routers, D denotes the set of destination addresses from the router, and t is the time stamp. Let | f i j ( u i , d j , t ) | represent the number of packets of flow f i j at time t. For a given time interval Δ T , the variation of the number of packets for a given flow is defined as
N i j ( u i , d j , t + Δ t ) | f i j ( u i , d j , t + Δ T ) | | f i j ( u i , d j , t ) | .
If | f i j ( u i , d j , t ) | = 0 , then N i j ( u i , d j , t + Δ T ) is the number of packets of flow f i j that went through the router during time interval Δ T . The quantity
p i j ( u i , d j , t + Δ T ) = N i j ( u i , d j , t + Δ T ) i = 1 j = 1 N i j ( u i , d j , t + Δ T ) ,
gives the probability of the flow f i j over all flows at the router with
i = 1 j = 1 p i j ( u i , d j , t + Δ T ) = 1 .
The computation of the Shannon entropy (1) at the router is obtained through
H ( F ) = i , j p i j ( u i , d j , t + Δ T ) log p i j ( u i , d j , t + Δ T ) ,
where F is the associated random variable with respect to flows during Δ T . If the total number of flows is constrained to N, then (6) is rather simply
H ( F ) = H ( p 1 , p 2 , , p N ) = i = 1 N p i log p i ,
with 0 H ( F ) log N . The lower bound occurs when there is only one flow.
In order to model a DDoS attack, a number of assumptions are made. These are that there is no extraordinary change of traffic in a very short time for the non-attack case, the number of attack packets is at least an order of magnitude higher than that of normal flows, there is only one attack ongoing at a time, and the number of flows is stable for both non-attack and attack cases.
Suppose attack flows start passing through the router at t = ( n + 1 ) τ ; hence, t = n τ signifies the time at the router just before the attack. The respective distributions are
{ p 1 ( n + 1 ) τ , p 2 ( n + 1 ) τ , , p N ( n + 1 ) τ } ,
{ p 1 n τ , p 2 n τ , , p N n τ } .
A consequence of the assumptions is that p k n τ p k ( n + 1 ) τ for some k. Further reasoning with Jensen’s inequality leads to
i = 1 N p i n τ log p i n τ i = 1 N p i ( n + 1 ) τ log p i ( n + 1 ) τ .
Expressing this in terms of the entropy (7) gives
H ( F n τ ) H ( F ( n + 1 ) τ ) .
The entropy at the router drops dramatically as soon as attack flows are passing through, thereby allowing for an ability to detect an attack as early as possible.

3. Quantum Networks

Quantum networks [4] generate entanglement over long distances. These entanglement flows are routed through devices known as repeaters [20,21], which perform entanglement swapping to connect two spatially entangled links into a longer entangled link.
To illustrate an instantiation of this task, we will utilize Bell states
| β x y = | 0 | y + ( 1 ) x | 1 | y ¯ 2 ,
where the bar denotes negation and we have a choice between x y = 00 , 01 , 10 , or 11. With respect to the computational basis states, the quantum information in the Bell state (12) takes the form
y ¯ 2 , y 2 , ( 1 ) x y 2 , ( 1 ) x y ¯ 2 .
Consider a quantum network which has to perform a routing task between two nodes. A request node needs to share a Bell state with a receiver node, with the constraint that the request node is unable to directly communicate with the receiver node. Despite the apparent difficulty, this task can be accomplished through the use of a quantum repeater located at another node.
We start by generating Bell pairs at both the request node (qubits A and B) and the repeater node (qubits C and D). One qubit (B) of the request pair reaches the repeater to be Bell projected with a qubit (C) at the repeater.
The joint state can be written as
| Request | Repeater | β 00 A , B | β x y C , D = 1 2 ( | β x y A , D | β 00 B , C ) + | β x ¯ y A , D | β 10 B , C + ( 1 ) x | β x y ¯ A , D | β 01 B , C + ( 1 ) x | β x ¯ y ¯ A , D | β 11 B , C .
The repeater performs a Bell state projection on B C . This returns one of four possible outcomes with consequences for A D :
| β 00 B , C | β x y A , D | β 01 B , C ( 1 ) x | β x y ¯ A , D | β 10 B , C | β x ¯ y A , D | β 11 B , C ( 1 ) x | β x ¯ y ¯ .
Depending on the outcome, the repeater applies a particular unitary operator to qubit D:
( I I ) | β x y A , D , ( I ( 1 ) x σ ^ 1 ) ( 1 ) x | β x y ¯ A , D , ( I ( 1 ) y σ ^ 3 ) | β x ¯ y A , D , ( I ( 1 ) x + y σ ^ 3 σ ^ 1 ) ( 1 ) x | β x ¯ y ¯ A , D ,
where σ ^ 1 = | 0 1 | + | 1 0 | , σ ^ 2 = i | 0 1 | + i | 1 0 | and σ ^ 3 = | 0 0 | | 1 1 | . Afterwards, the non-projected qubit (D) of the repeater pair leaves towards the destination node. This results in the desired output of having state | β x y A , D shared between the request node and receiver.
We want to view this procedure in terms of the von Neumann quantum entropy [1], which is defined as
S ( ρ ) Tr ( ρ log ρ ) ,
where ρ is a density operator. The entropy is zero if and only if it is a pure state. For an arbitrary composite system with subsystems K and L, the joint and conditional entropy are
S ( ρ K L ) Tr ( ρ K L log ρ L K ) ,
S ( ρ K | ρ L ) S ( ρ K L ) S ( ρ L ) ,
where ρ K = Tr L ( ρ K L ) and ρ L = Tr K ( ρ K L ) . Suppose ρ K L is a pure state; then, ρ K L is entangled if and only if
S ( ρ K | ρ L ) < 0 .
In this case, the entropy of either subsystem, S ( ρ K ) or S ( ρ L ) , is referred to as the entanglement entropy.
In the repeater, the density operator is
ρ C , D = | β x y B , C β x y | B , C ,
and the associated conditional entropy is
S ( ρ C | ρ D ) = S ( ρ C , D ) S ( ρ D ) = 0 1 = 1 ,
which indicates entanglement (20) as expected. Note that at the time before projection, qubits A and D are not entangled
S ( ρ A | ρ D ) = S ( ρ A , D ) S ( ρ D ) = 2 1 = 1 .
For the output state, the density operator takes the form
ρ A , D = | β x y A , D β x y | A , D ,
and the associated conditional entropy is
S ( ρ A | ρ D ) = S ( ρ A , D ) S ( ρ D ) = 0 1 = 1 ,
signifying entanglement, with a loss of it in
S ( ρ C | ρ D ) = S ( ρ C , D ) S ( ρ D ) = 2 1 = 1 .
In terms of the joint entropy, just before projection (22), we see that S ( ρ C , D ) = 0 , which specifies a pure state. After projection (26), we have that S ( ρ C , D ) = 2 , which signifies missing information in C D . Part of that missing information moved, as described by the updated entropy S ( ρ A , D ) = 0 in the output | β x y A , D .

4. Quantum DDoS

Quantum networks can also experience DDoS attacks [10,22], which poses a significant threat to its quantum key distribution protocols [7,11]. Given that quantum repeaters have a maximum session capacity [23], we consider DDoS attacks on a repeater where service requests exceed that maximum capacity.
The entanglement entropy will be used to formulate a DDoS detection system analogous to the classical case (11). To derive this, we utilize various aspects of the material in [24] towards our specific application.
Our model starts with the request node generating | β 00 A , B , with qubit B being sent to the repeater. The repeater generates | β 00 C , D , which can be viewed as an instantiation of | β x y C , D .
We consider the quantities before the projection. The total system is ρ A , B , C , D , which denotes
| β 00 A , B | β 00 C , D β 00 | A , B β 00 | C , D ,
and the subsystem held at the repeater is ρ B , C , D , as it excludes ρ A . Given qubits C and D are jointly in a pure state, we have that
S ( ρ B , C , D ) = S ( ρ B ) = 1 .
The qubit B is maximally mixed, since it is entangled with qubit A in a Bell state. Thus, the entanglement entropy of qubit A before the projection equates to
S ( ρ A ) = S ( ρ B , C , D ) .
We take the partial trace to obtain the density operator for qubit D
ρ D = Tr A B C ( ρ A , B , C , D ) .
We have that S ( ρ D ) = 1 , since it is entangled with ρ C .
The entanglement entropy forms a crucial role for a repeater session. A successful session occurs when the entanglement is swapped (15). The swapping is successful only if the repeater uses some rank-one orthogonal projectors Π i such that no matter what outcome occurs at the repeater on qubits B and C, the value of the entanglement entropy of ρ A before projection must equal the value of the entanglement entropy of ρ A after projection.
We proceed to examine the quantities after the projection. If the repeater obtains outcome i, then the density operator of D is
ρ D i = 1 p i Tr A B C ( Π i ρ A , B , C , D ) ,
where p i is the associated Born probability. Given
i Π i = I ,
we have that
ρ D = i p i ρ D i .
After measurement, qubits A and D are in a pure entangled state. The entanglement entropy of D equates to the entanglement entropy of A after projection
S ( ρ D i ) = S ( ρ A ) .
Using the crucial condition that a successful session requires the entropy before projection and entropy after projection of ρ A to equate, we can formulate relationships between the quantities before and after projection. Specifically, using (29) and (34), we obtain
S ( ρ D i ) = S ( ρ B , C , D ) ,
and furthermore
S ( ρ B , C , D ) = S ( ρ D i ) = i p i S ( ρ D i ) .
Applying the concavity inequality [24] to (33) results in
S ( ρ D ) i p i S ( ρ D i ) .
Combining (36) and (37) gives
S ( ρ B , C , D ) = i p i S ( ρ D i ) S ( ρ D ) .
Therefore, before the projection, one can predict that a successful session is possible when and only when
S ( ρ B , C | ρ D ) = S ( ρ B , C , D ) S ( ρ D ) 0 .
A failed session will occur when S ( ρ B , C | ρ D ) > 0 . For our specific case (27), we have that S ( ρ B , C | ρ D ) = 0 , which implies a successful session ahead.
The capacity of the repeater is defined as the maximum number of sessions it can facilitate simultaneously, and this is directly related to the number of Bell pairs that can be stored in memory [23]. In our case, this would be the maximum number of copies of ρ C , D generated at a time to keep the service at full capacity. After that time, any unused Bell pairs get destroyed, and the system regenerates to full capacity at the next time point.
With respect to capacity, we modify our previous analysis to N copies of system ρ A , B , C , D for a large N. The repeater would perform a complete projective measurement on ( ρ B , C ) N . In this case, all the entropies are multiplied by N. Hence, the condition (39) for sessions is maintained, and we can interpret it in terms of capacity.
In [24], it was shown that a negative conditional entropy in an entanglement-swapping protocol equals the number of left Bell pairs. Harnessing this reasoning in our quantum repeater scenario implies that if we have S ( ρ B , C | ρ D ) < 0 before the projection, then S ( ρ B , C | ρ D ) is the number of Bell pairs left afterwards in the memory. It can be viewed as quantifying the unused capacity after the session requests have been fulfilled. If S ( ρ B , C | ρ D ) > 0 , it not possible to carry out a session to begin with, and the system predicts an unresponsive service due to requests exceeding the capacity. Therefore, (39) can be used to model a DDoS attack.
To design a detection system, suppose a flood of attack requests reaches a repeater at specific time t = ( n + 1 ) τ . We make the same assumptions about the network traffic of the attack requests as in the previous classical case. For example, here we also assume the number of attack requests is at least an order of magnitude higher than that of normal requests. The entropy of the requests at the repeater is quantified as
S ( ρ B n τ ) S ( σ B ( n + 1 ) τ ) ,
where ρ is used to label the systems involved prior to attack, and σ denotes the systems involved in the attack (the superscripts signify the respective times). The repeater generates the same full capacity at each time point; hence,
S ( ρ C , D n τ , n τ ) = S ( σ C , D ( n + 1 ) τ , ( n + 1 ) τ ) ,
and with (40), we obtain
S ( ρ B , C , D n τ , n τ , n τ ) S ( σ B , C , D ( n + 1 ) τ , ( n + 1 ) τ , ( n + 1 ) τ ) .
From (41), we have that
S ( ρ D n τ ) = S ( σ D ( n + 1 ) τ ) .
Combining this with (42) produces an entropic DDoS detection formula at the repeater
S ( ρ B , C n τ , n τ | ρ D n τ ) S ( σ B , C ( n + 1 ) τ , ( n + 1 ) τ | σ D ( n + 1 ) τ ) .
The conditional entropies in (44) encode both the requests and the capacity, thereby providing a mechanism for early detection of a DDoS attack. In an attack, this entropy increases dramatically at the repeater, signifying a drastic reduction in capacity.
It is important to note that in this attack scenario, the capacity for service may still be available, in that (39) is still satisfied. What is of importance to the detection system (for early detection) is that there has been a drastic change in capacity, as expressed through (44). Hence, we use (44) to detect the attack. This line of reasoning follows from the classical system, and thus, in this work we have provided a quantum DDoS detection system that is analogous to the classical case (11).

5. Discussion

To address implementation, a large number of low-level design features need to be addressed. One issue is for the node to compute the quantum entropy using some subset of the network traffic. Various quantum algorithms for calculating entropy have been developed [25,26,27], and future work would involve integrating these methods for a refined detection system.
In classical networks, after detecting a DDoS attack, it is common to employ a mitigation method [8]. As a result, the service capacity is unaffected, leaving service available to legitimate traffic. Future work on our quantum DDoS case could involve developing mitigation methods based on quantum resources.
We illustrate this with a simple method that could be used to develop a more sophisticated strategy. Suppose we have attack Bell states | β 00 A 1 B 1 ( n + 1 ) τ , ( n + 1 ) τ and | β 00 A 2 B 2 ( n + 1 ) τ , ( n + 1 ) τ . The labels A 1 and A 2 refer to the qubits at the respective attack nodes, and labels B 1 and B 2 are the qubits that reach the repeater at t = ( n + 1 ) τ (see Appendix A). Under normal conditions, the repeater would perform a projection with the Bell pairs generated at the repeater.
Given that the attack has been detected, the repeater performs a joint projective measurement on the attack qubits themselves, B 1 and B 2 at t = ( n + 1 ) τ . We can write this as
(45) | β 00 A 1 B 1 ( n + 1 ) τ , ( n + 1 ) τ | β 00 A 2 B 2 ( n + 1 ) τ , ( n + 1 ) τ = 1 2 ( | β 00 A 1 A 2 ( n + 1 ) τ , ( n + 1 ) τ | β 00 B 1 B 2 ( n + 1 ) τ , ( n + 1 ) τ ) (46) + | β 01 A 1 A 2 ( n + 1 ) τ , ( n + 1 ) τ | β 01 B 1 B 2 ( n + 1 ) τ , ( n + 1 ) τ + | β 10 A 1 A 2 ( n + 1 ) τ , ( n + 1 ) τ | β 10 B 1 B 2 ( n + 1 ) τ , ( n + 1 ) τ + | β 11 A 1 A 2 ( n + 1 ) τ , ( n + 1 ) τ | β 11 B 1 B 2 ( n + 1 ) τ , ( n + 1 ) τ .
This joint measurement would swap the entanglement to qubits A 1 and A 2 , which are at the attack nodes. Consequently, the Bell pairs generated at the repeater are not used, thereby leaving the repeater’s capacity available for legitimate traffic.
In a large classical network, it is advantageous to devise a traceback method [19] so to identify the source of the attack. Both classical and quantum networks can be modelled as a directed acyclic graphs, where the upstream routers could be viewed as parent nodes and the downstream routes as children nodes. Hence, an interesting direction would be to employ quantum causal models [28] to provide a traceback model for DDoS attacks on a quantum network. The attacks could be formulated in terms of do-interventions and would allow the ability to apply a quantum do-calculus or a quantum causal discovery algorithm to carry out successful traceback for a DDoS attack on a quantum network.
There are a number of ways in which this research could be extended for more practical scenarios. One direction would be to investigate how this entropic detection system could be modified for near-term quantum networks, such as trusted relay networks.
Another research direction would be to explore how this work translates into repeater scenarios involving mixed states. Such cases are of practical importance for quantum networks given channel noise and the imperfections of local devices. One possibility for such modeling is to utilize Werner states for the entanglement swapping protocol and to derive analogous results.
Furthermore, one can consider cases involving multiple repeaters to generate entanglement over farther and farther distances. For such practical cases and where mixed states are employed, the entanglement decreases exponentially with the number of swappings. Finding potential DDoS attacks within such scenarios and designing the associated entropic DDoS detection systems is left for future work.

6. Conclusions

DDoS attacks are a central topic in classical network security and have been identified to be significant threat tp quantum networks. In this work, we designed a quantum analogue of a classical DDoS detection system and applied it in the context of a quantum network. We hope that our design contributes to extending the applicability of quantum information from the domain of data security to area of network security.

Funding

This research received no external funding.

Data Availability Statement

Not applicable.

Acknowledgments

The author thanks Winston Seah (Victoria University of Wellington) for helpful discussions.

Conflicts of Interest

The author declares no conflict of interest. This paper was prepared for informative purposes and is not a product of HSBC Bank Plc. or its affiliates. Neither HSBC Bank Plc. nor any of its affiliates make any explicit or implied representation or warranty, and none of them accept any liability in connection with this paper, including, but limited to, the completeness, accuracy, and reliability of information contained herein and the potential legal, compliance, tax, or accounting effects thereof. This document is not intended as investment research or investment advice; or a recommendation, offer, or solicitation for the purchase or sale of any security, financial instrument, financial product, or service; or to be used in any way for evaluating the merits of participating in any transaction.

Abbreviations

The following abbreviations are used in this manuscript:
DDoSDistributed Denial-of-Service

Appendix A

Derivation of equations in main text:
| β 00 A , B | β x y C , D = | 00 A , B + | 11 A , B 2 | 0 y C , D + ( 1 ) x | 1 y ¯ C , D 2
= 1 2 ( | 00 A , B | 0 y C , D + ( 1 ) x | 00 A , B | 1 y ¯ C , D
+ | 11 A , B | 0 y C , D + ( 1 ) x | 11 A , B | 1 y ¯ C , D )
= 1 2 ( | 0 y A , D | 00 B , C + ( 1 ) x | 0 y ¯ A , D | 01 B , C
+ | 1 y A , D | 10 B , C + ( 1 ) x | 1 y ¯ A , D | 11 B , C )
= 1 4 [ 2 | 0 y A , D | 00 B , C + 2 ( 1 ) x | 1 y ¯ A , D | 11 B , C
+ 2 ( 1 ) x | 0 y ¯ A , D | 01 B , C + 2 | 1 y A , D | 10 B , C ]
= 1 2 [ 1 2 ( | 0 y A , D | 00 B , C + | 0 y A , D | 11 B , C
+ ( 1 ) x | 1 y ¯ A , D | 00 B , C + ( 1 ) x | 1 y ¯ A , D | 11 B , C )
+ 1 2 ( | 0 y A , D | 00 B , C | 0 y A , D | 11 B , C
+ ( 1 ) x ¯ | 1 y ¯ A , D | 00 B , C ( 1 ) x ¯ | 1 y ¯ A , D | 11 B , C )
+ 1 2 ( ( 1 ) x | 0 y ¯ A , D | 01 B , C + ( 1 ) x | 0 y ¯ A , D | 10 B , C
+ | 1 y A , D | 01 B , C + | 1 y A , D | 10 B , C )
+ 1 2 ( ( 1 ) x | 0 y ¯ A , D | 01 B , C ( 1 ) x | 0 y ¯ A , D | 10 B , C
| 1 y A , D | 01 B , C + | 1 y A , D | 10 B , C ) ]
= 1 2 [ | 0 y A , D + ( 1 ) x | 1 y ¯ A , D 2 | 00 B , C + | 11 B , C 2
+ | 0 y A , D + ( 1 ) x ¯ | 1 y ¯ A , D 2 | 00 B , C | 11 B , C 2
+ ( 1 ) x | 0 y ¯ A , D + ( 1 ) 2 x | 1 y A , D 2 | 01 B , C + | 10 B , C 2
+ ( 1 ) x | 0 y ¯ A , D + ( 1 ) x + x ¯ | 1 y A , D 2 | 01 B , C | 10 B , C 2 ]
= 1 2 ( | β x y A , D | β 00 B , C + | β x ¯ y A , D | β 10 B , C ) + ( 1 ) x | β x y ¯ A , D | β 01 B , C + ( 1 ) x | β x ¯ y ¯ A , D | β 11 B , C .
We also applied the following operators to the respective states to obtain the outcome | β x y A , D :
( I ( 1 ) x σ ^ 1 ) ( 1 ) x | β x y ¯ A , D = ( I ( 1 ) x σ ^ 1 ) ( 1 ) x | 0 y ¯ A , D + | 1 y A , D 2
= 1 2 ( | 0 A ( 1 ) x ( 1 ) x σ ^ 1 | y ¯ D )
+ 1 2 ( | 1 A ( 1 ) x σ ^ 1 | y D )
= 1 2 ( | 0 A ( 1 ) x + x | y D )
+ 1 2 ( | 1 A ( 1 ) x | y ¯ D )
= 1 2 ( | 0 A | y D )
+ 1 2 ( ( 1 ) x | 1 A | y ¯ D )
= | 0 y A , D + ( 1 ) x | 1 y ¯ A , D 2
= | β x y A , D
( I ( 1 ) y σ ^ 3 ) | β x ¯ y A , D = ( I ( 1 ) y σ ^ 3 ) | 0 y A , D + ( 1 ) x ¯ | 1 y ¯ A , D 2
= 1 2 ( | 0 A ( 1 ) y σ ^ 3 | y D )
+ 1 2 ( | 1 A ( 1 ) y ( 1 ) x ¯ σ ^ 3 | y ¯ D )
= 1 2 ( | 0 A ( 1 ) y ( 1 ) y | y D )
+ 1 2 ( | 1 A ( 1 ) y ( 1 ) x ¯ ( 1 ) y ¯ | y ¯ D )
= 1 2 ( | 0 A ( 1 ) y + y | y D )
+ 1 2 ( | 1 A ( 1 ) y + y ¯ ( 1 ) x ¯ | y ¯ D )
= 1 2 ( | 0 A | y D )
+ 1 2 ( | 1 A ( 1 ) ( 1 ) x ¯ | y ¯ D )
= 1 2 ( | 0 A | y D )
+ 1 2 ( | 1 A ( 1 ) x | y ¯ D )
= | 0 y A , D + ( 1 ) x | 1 y ¯ A , D 2
= | β x y A , D
( I ( 1 ) x + y σ ^ 3 σ ^ 1 ) ( 1 ) x | β x ¯ y ¯ A , D = ( I ( 1 ) x + y σ ^ 3 σ ^ 1 ) ( 1 ) x | 0 y ¯ A , D | 1 y A , D 2
= 1 2 ( | 0 A ( 1 ) x ( 1 ) x + y σ ^ 3 σ ^ 1 | y ¯ D )
| 1 A ( 1 ) x + y σ ^ 3 σ ^ 1 | y D )
= 1 2 ( | 0 A ( 1 ) x ( 1 ) x + y ( 1 ) y | y D )
| 1 A ( 1 ) x + y ( 1 ) y ¯ | y ¯ D )
= 1 2 ( | 0 A ( 1 ) x + y + x + y | y D )
| 1 A ( 1 ) x + y + y ¯ | y ¯ D )
= 1 2 ( | 0 A | y D )
| 1 A ( 1 ) x | y ¯ D )
= 1 2 ( | 0 A | y D )
+ ( 1 ) x | 1 A | y ¯ D )
= | 0 y A , D + ( 1 ) x | 1 y ¯ A , D 2
= | β x y A , D

References

  1. Nielsen, M.A.; Chuang, I.L. Quantum Computation and Quantum Information; Cambridge University Press: Cambridge, UK, 2010. [Google Scholar]
  2. Arute, F.; Arya, K.; Babbush, R.; Bacon, D.; Bardin, J.C.; Barends, R.; Biswas, R.; Boixo, S.; Brandao, F.G.S.L.; Buell, D.A.; et al. Quantum supremacy using a programmable superconducting processor. Nature 2019, 574, 505–510. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  3. Wu, Y.; Bao, W.S.; Cao, S.; Chen, F.; Chen, M.C.; Chen, X. Strong quantum computational advantage using a superconducting quantum processor. Phys. Rev. Lett. 2021, 127, 180501. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  4. Wehner, S.; Elkouss, D.; Hanson, R. Quantum internet: A vision for the road ahead. Science 2018, 362, 6412. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  5. Bennett, C.H.; Brassard, G.; Crepeau, C.; Jozsa, R.; Peres, A.; Wootters, W.K. Teleporting an unknown quantum state via dual classical and Einstein–Podolsky-Rosen channels. Phys. Rev. Lett. 1993, 70, 1895–1899. [Google Scholar] [CrossRef] [Scilit]
  6. Ren, J.G.; Xu, P.; Yong, H.L.; Zhang, L.; Liao, S.K.; Yin, J.; Liu, W.; Cai, W.; Yang, M.; Li, L.; et al. Ground-to-satellite quantum teleportation. Nature 2017, 549, 70–73. [Google Scholar] [CrossRef] [Scilit]
  7. Xu, F.; Ma, X.; Zhang, Q.; Lo, H.K.; Pan, J.W. Secure quantum key distribution with realistic devices. Rev. Mod. Phys. 2020, 92, 025002. [Google Scholar] [CrossRef] [Scilit]
  8. Osterweil, E.; Stavrou, A.; Zhang, L. 21 years of distributed denial-of-service: A call to action. Computer 2020, 53, 94–99. [Google Scholar] [CrossRef] [Scilit]
  9. Mahjabin, T.; Xiao, Y.; Sun, G.; Jiang, W. A survey of distributed denial-of-service attack, prevention, and mitigation techniques. Int. J. Distrib. Sens. Netw. 2017, 13, 1550147717741463. [Google Scholar] [CrossRef] [Scilit]
  10. Satoh, T.; Nagayama, S.; Suzuki, S.; Matsuo, T.; Hajdušek, M.; Meter, R.V. Attacking the quantum internet. IEEE Trans. Quantum Eng. 2021, 2, 1–17. [Google Scholar] [CrossRef] [Scilit]
  11. Clark, R.; Bartlett, S.; Bremner, M.; Lam, P.K.; Ralph, T. The Impact of Quantum Technologies on Secure Communications; Australian Strategic Policy Institute: Canberra, Australia, 2021; pp. 1–47. [Google Scholar]
  12. Price, A.B.; Rarity, J.G.; Erven, C. A quantum key distribution protocol for rapid denial of service detection. EPJ Quantum Technol. 2020, 7, 8. [Google Scholar] [CrossRef] [Scilit]
  13. Lesk, M. The new front line: Estonia under cyberassault. IEEE Secur. Priv. 2007, 5, 76–79. [Google Scholar] [CrossRef] [Scilit]
  14. Mansfield-Devine, S. The growth and evolution of DDoS. Netw. Secur. 2015, 13–20. [Google Scholar] [CrossRef] [Scilit]
  15. Kathirkamanathan, N.; Thevarasa, B.; Mahadevan, G.; Skandhakumar, N.; Kuruwitaarachchi, N. Prevention of DDoS attacks targeting financial services using supervised machine learning and stacked LSTM. In Proceedings of the IEEE 7th International Conference for Convergence in Technology, Mumbai, India, 7–9 April 2022; pp. 1–5. [Google Scholar]
  16. Financial Markets Authority. Market Operator Obligations Targeted Review–NZX; Financial Markets Authority New Zealand: Wellington, New Zealand, 2021; pp. 1–19.
  17. Koay, A. Detecting High and Low Intensity Distributed Denial of Service (DDoS) Attacks. Ph.D. Thesis, Victoria University of Wellington, Wellington, New Zealand, 2019. [Google Scholar]
  18. Özçelik, İ.; Brooks, R.R. Deceiving entropy based DoS detection. Comput. Secur. 2015, 48, 234–245. [Google Scholar] [CrossRef] [Scilit]
  19. Yu, S.; Zhou, W.; Doss, R.; Jia, W. Traceback of DDoS attacks using entropy variations. IEEE Trans. Parallel Distrib. Syst. 2010, 22, 412–425. [Google Scholar] [CrossRef] [Scilit]
  20. Pant, M.; Krovi, H.; Towsley, D.; Tassiulas, L.; Jiang, L.; Basu, P.; Englund, D.; Guha, S. Routing entanglement in the quantum internet. NPJ Quantum Inf. 2019, 5, 1–9. [Google Scholar] [CrossRef] [Scilit]
  21. Lee, Y.; Bersin, E.; Dahlberg, A.; Wehner, S.; Englund, D. A quantum router architecture for high-fidelity entanglement flows in quantum networks. NPJ Quantum Inf. 2022, 8, 1–8. [Google Scholar] [CrossRef] [Scilit]
  22. Dai, E.; Huang, D.; Zhang, L. Low-rate denial-of-service attack detection: Defense strategy based on spectral estimation for CV-QKD. Photonics 2022, 9, 365. [Google Scholar] [CrossRef] [Scilit]
  23. Rabbie, J.; Chakraborty, K.; Avis, G.; Wehner, S. Designing quantum networks using preexisting infrastructure. NPJ Quantum Inf. 2022, 8, 1–12. [Google Scholar] [CrossRef] [Scilit]
  24. Witten, E. A mini-introduction to information theory. La Riv. del Nuovo C. 2020, 43, 187–227. [Google Scholar] [CrossRef] [Scilit]
  25. Acharya, J.; Issa, I.; Shende, N.V.; Wagner, A.B. Measuring quantum entropy. In Proceedings of the 2019 IEEE International Symposium on Information Theory, Paris, France, 7–12 July 2019; pp. 3012–3016. [Google Scholar]
  26. Wang, Y.; Zhao, B.; Wang, X. Quantum algorithms for estimating quantum entropies. arXiv 2022, arXiv:2203.02386. [Google Scholar]
  27. Wang, Q.; Guan, J.; Liu, J.; Zhang, Z.; Ying, M. New quantum algorithms for computing quantum entropies and distances. arXiv 2022, arXiv:2203.13522. [Google Scholar]
  28. Barrett, J.; Lorenz, R.; Oreshkov, O. Cyclic quantum causal models. Nat. Commun. 2021, 12, 1–15. [Google Scholar] [CrossRef] [Scilit] [PubMed]
Publisher’s Note: MDPI stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.